External risk intelligence

Google Chrome Use After Free Vulnerability Allows Arbitrary Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95299

The vulnerability exists within a web browser, which is designed for public-facing internet navigation and is frequently exposed to untrusted external content. As a client-side application inherently used to interact with the public internet by design, the attack surface is considered very likely to be reachable.

Use After Free

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Google Chrome, specifically a "use after free" flaw in the GPU component, could allow an attacker to execute malicious code outside the browser's secure environment. This is achieved by tricking a user into visiting a specially crafted web page. While the severity is high, the primary concern for leadership is to confirm if this specific technology is in use and if exposure is possible.

  • Browser code flaw allows remote code execution.
  • High risk if users visit malicious websites.
  • Confirm if Chrome is used and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could draw a victim into visiting a malicious website, which would then present a specially crafted HTML page to the user's browser. This page would exploit a use-after-free vulnerability within the browser's graphics processing unit (GPU) component. Successful exploitation could allow the attacker to execute code on the victim's machine, bypassing security sandboxing.

  • Requires no special access.
  • Triggered by visiting a malicious webpage.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A remote attacker could potentially execute arbitrary code outside the browser's sandbox when a user visits a malicious HTML page. This could impact the integrity and confidentiality of system data.

  • Arbitrary code execution.
  • Via a crafted HTML page.
  • Compromise of system data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The identified use-after-free vulnerability in Google Chrome's GPU component requires swift action from teams responsible for end-user computing, browser management, and security operations. The immediate priority is to identify all instances of the affected Chrome version within the organization, assess their exposure to potentially malicious web content, and confirm the business criticality of any systems running this version. Once accountable owners are identified, a coordinated remediation plan, considering potential maintenance windows and vendor coordination, should be established to mitigate the risk of arbitrary code execution outside the sandbox.

  • Browser and endpoint teams own remediation.
  • Verify Chrome browser exposure and criticality.
  • Plan and coordinate Chrome browser updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome and why does it have a GPU component?

Google Chrome is a web browser used to access the internet. It includes a Graphics Processing Unit (GPU) component to offload visual rendering tasks—like displaying complex web pages, animations, and videos—to the computer's graphics hardware, ensuring a smooth and responsive browsing experience.

What does a use-after-free vulnerability mean in CVE-2026-95299?

A use-after-free is a memory management error (CWE-416). It happens when software continues to use a memory location after it has been cleared or deleted. In this case, an attacker can manipulate this flaw to replace the old data with malicious instructions, causing the browser to execute them unexpectedly.

How is this Chrome vulnerability triggered?

The flaw is triggered when a user navigates to a specially crafted HTML page designed to exploit the GPU memory error. It does not trigger simply by having the browser installed or running; it requires the active rendering of malicious web content.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal notes that because Chrome is a web browser built to process untrusted internet content, it is inherently internet-facing. This makes the vulnerability highly reachable if you use the affected version, as any standard web navigation to a malicious site could trigger the issue.

What steps should I take to address CVE-2026-95299?

The primary response is to update Google Chrome to version 154.0.8037.57 or later. You should identify all systems in your environment running older versions and prioritize applying the vendor-provided update to ensure the browser's sandbox protections are properly restored.

References